CVE-2019-9506
published 2019-08-14CVE-2019-9506: The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from…
PriorityP345high8.1CVSS 3.1
AVAACLPRNUINSUCHIHAN
EPSS
2.69%
84.2th percentile
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.
Affected
150 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | macos_mojave_10.14.6_security_update_2019-004_high_sierra_security_update_2019-0 | — | — |
| apple | tvos | — | — |
| apple | tvos | — | — |
| apple | watchos | — | — |
| apple | watchos | — | — |
| bluetooth | br_edr | 5.1 – 5.1 | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 5.2.6-1 (bookworm) | linux 5.2.6-1 (bookworm) |
| android | — | — | |
| huawei | alp-al00b_firmware | < 9.1.0.333\(c00e333r2p1t8\) | 9.1.0.333\(c00e333r2p1t8\) |
| huawei | ares-al00b_firmware | < 9.1.0.160\(c00e160r2p5t8\) | 9.1.0.160\(c00e160r2p5t8\) |
| huawei | ares-al10d_firmware | < 9.1.0.160\(c00e160r2p5t8\) | 9.1.0.160\(c00e160r2p5t8\) |
| huawei | ares-tl00c_firmware | < 9.1.0.165\(c01e165r2p5t8\) | 9.1.0.165\(c01e165r2p5t8\) |
| huawei | asoka-al00ax_firmware | < 9.1.1.181\(c00e48r6p1\) | 9.1.1.181\(c00e48r6p1\) |
| huawei | atomu-l33_firmware | < 8.0.0.147\(c605custc605d1\) | 8.0.0.147\(c605custc605d1\) |
| huawei | atomu-l41_firmware | < 8.0.0.153\(c461custc461d1\) | 8.0.0.153\(c461custc461d1\) |
| huawei | atomu-l42_firmware | < 8.0.0.155\(c636custc636d1\) | 8.0.0.155\(c636custc636d1\) |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv3.07.6HIGHCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
nvdv2.04.8MEDIUMAV:A/AC:L/Au:N/C:P/I:P/A:N
osv8.1HIGH
vendor_cisco9.3CRITICAL
vendor_msrc9.3CRITICAL
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
vendor_ubuntu7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-10-04·CVSS 7.4
CVE-2019-0136 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the Intel Wi-Fi device driver in the Linux kernel
did not properly validate certain Tunneled Direct Link Setup (TDLS). A
physically proximate attacker could use this to cause a denial of service
(Wi-Fi disconnect). (CVE-2019-0136)
It was discovered that the Bluetooth UART implementation in the Linux
kernel did not properly check for missing tty operations. A local attacker
could use this to cause a denial of service. (CVE-2019-10207)
It was discovered that the GTCO tablet input driver in the Linux kernel did
not properly bounds check the initial HID report sent by the device. A
physically proximate attacker could use this to cause a denial of service
(system crash
Ubuntu
Linux kernel regression
vendor_ubuntu·2019-09-11·CVSS 4.6
[MEDIUM] Linux kernel regression
Title: Linux kernel regression
Summary: USN 4115-1 introduced a regression in the Linux kernel.
USN 4115-1 fixed vulnerabilities in the Linux 4.15 kernel for Ubuntu
18.04 LTS and Ubuntu 16.04 LTS. Unfortunately, as part of the update,
a regression was introduced that caused a kernel crash when handling
fragmented packets in some situations. This update addresses the issue.
We apologize for the inconvenience.
Original advisory details:
Hui Peng and Mathias Payer discovered that the Option USB High Speed driver
in the Linux kernel did not properly validate metadata received from the
device. A physically proximate attacker could use this to cause a denial of
service (system crash). (CVE-2018-19985)
Zhipeng Xie discovered that an infinite loop could triggered in the CFS
Linux kernel proc
Ubuntu
Linux kernel (AWS) vulnerabilities
vendor_ubuntu·2019-09-02·CVSS 3.3
CVE-2018-13053 [LOW] Linux kernel (AWS) vulnerabilities
Title: Linux kernel (AWS) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the alarmtimer implementation in the Linux kernel
contained an integer overflow vulnerability. A local attacker could use
this to cause a denial of service. (CVE-2018-13053)
Wen Xu discovered that the XFS filesystem implementation in the Linux
kernel did not properly track inode validations. An attacker could use this
to construct a malicious XFS image that, when mounted, could cause a denial
of service (system crash). (CVE-2018-13093)
Wen Xu discovered that the f2fs file system implementation in the Linux
kernel did not properly validate metadata. An attacker could use this to
construct a malicious f2fs image that, when mounted, could cause a denial
of serv
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-09-02·CVSS 4.6
CVE-2018-19985 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Hui Peng and Mathias Payer discovered that the Option USB High Speed driver
in the Linux kernel did not properly validate metadata received from the
device. A physically proximate attacker could use this to cause a denial of
service (system crash). (CVE-2018-19985)
Zhipeng Xie discovered that an infinite loop could be triggered in the CFS
Linux kernel process scheduler. A local attacker could possibly use this to
cause a denial of service. (CVE-2018-20784)
It was discovered that the Intel Wi-Fi device driver in the Linux kernel did
not properly validate certain Tunneled Direct Link Setup (TDLS). A
physically proximate attacker could use this to cause a denial of service
(Wi-Fi disconnec
Microsoft
Encryption Key Negotiation of Bluetooth Vulnerability
vendor_msrc·2019-08-13·CVSS 9.3
CVE-2019-9506 [HIGH] Encryption Key Negotiation of Bluetooth Vulnerability
Encryption Key Negotiation of Bluetooth Vulnerability
Description: Executive Summary
Microsoft is aware of the Bluetooth BR/EDR (basic rate/enhanced data rate, known as "Bluetooth Classic") key negotiation vulnerability that exists at the hardware specification level of any BR/EDR Bluetooth device. An attacker could potentially be able to negotiate the offered key length down to 1 byte of entropy, from a maximum of 16 bytes.
To exploit this vulnerability, an attacker would need specialized hardware and would be limited by the range of the Bluetooth devices in use. Using this specialized equipment, they would need to be close enough to communicate and interfere with the legitimate transmissions being made wirelessly.
CERT/CC has issued CVE-2019-9506 and VU#918987 for this tampering vulnera
Cisco
Key Negotiation of Bluetooth Vulnerability
vendor_cisco·2019-08-13·CVSS 9.3
CVE-2019-9506 [CRITICAL] Key Negotiation of Bluetooth Vulnerability
Key Negotiation of Bluetooth Vulnerability
A weakness in the Bluetooth Basic Rate/Enhanced Data Rate (BR/EDR) protocol core specification exposes a vulnerability that could allow for an unauthenticated, adjacent attacker to perform a man-in-the-middle attack on an encrypted Bluetooth connection. The attack must be performed during negotiation or renegotiation of a paired device connection; existing sessions cannot be attacked.
The issue could allow the attacker to reduce the entropy of the negotiated session key that is used to secure a Bluetooth connection between a paired device and a host device. An attacker who can successfully inject a malicious message into a Bluetooth connection during session negotiation or renegotiation could cause the strength of the session key to be susceptibl
Red Hat
hardware: bluetooth: BR/EDR encryption key negotiation attacks (KNOB)
vendor_redhat·2019-08-10·CVSS 8.1
CVE-2019-9506 [HIGH] CWE-327 hardware: bluetooth: BR/EDR encryption key negotiation attacks (KNOB)
hardware: bluetooth: BR/EDR encryption key negotiation attacks (KNOB)
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.
A flaw was discovered in the Bluetooth protocol. An attacker within physical proximity to the Bluetooth connection could downgrade the encryption protocol to be trivially brute forced.
Mitigation: At this time there is no known mitigation if bluetooth hardware is to be continue to be used. Replacing the hardware with its wired version and disabling bluetooth may be a suitable alternative for
Android
CVE-2019-9506: Android Security Bulletin 2019-08-01
CVE: CVE-2019-9506
Severity: HIGH
Type: ID
Affected AOSP versions: 7
vendor_android·2019-08-01·CVSS 8.1
CVE-2019-9506 [HIGH] CVE-2019-9506: Android Security Bulletin 2019-08-01
CVE: CVE-2019-9506
Severity: HIGH
Type: ID
Affected AOSP versions: 7
Android Security Bulletin 2019-08-01
CVE: CVE-2019-9506
Severity: HIGH
Type: ID
Affected AOSP versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1, 9
References: A-124301137
[2]
Apple
CVE-2019-9506: iOS 12.4
vendor_apple·2019-07-22·CVSS 8.1
CVE-2019-9506 [HIGH] CVE-2019-9506: iOS 12.4
Apple Security Update: About the security content of iOS 12.4
Product: iOS
Version: 12.4
CVE: CVE-2019-9506
Component: Bluetooth
Impact: An attacker in a privileged network position may be able to intercept Bluetooth traffic (Key Negotiation of Bluetooth - KNOB)
Description: An input validation issue existed in Bluetooth. This issue was addressed with improved input validation.
Apple
CVE-2019-9506: macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra
vendor_apple·2019-07-22·CVSS 8.1
CVE-2019-9506 [HIGH] CVE-2019-9506: macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra
Apple Security Update: About the security content of macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra
Product: macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra
CVE: CVE-2019-9506
Component: Bluetooth
Impact: An attacker in a privileged network position may be able to intercept Bluetooth traffic (Key Negotiation of Bluetooth - KNOB)
Description: An input validation issue existed in Bluetooth. This issue was addressed with improved input validation.
Apple
CVE-2019-9506: tvOS 12.4
vendor_apple·2019-07-22·CVSS 8.1
CVE-2019-9506 [HIGH] CVE-2019-9506: tvOS 12.4
Apple Security Update: About the security content of tvOS 12.4
Product: tvOS
Version: 12.4
CVE: CVE-2019-9506
Component: Bluetooth
Impact: An attacker in a privileged network position may be able to intercept Bluetooth traffic (Key Negotiation of Bluetooth - KNOB)
Description: An input validation issue existed in Bluetooth. This issue was addressed with improved input validation.
Apple
CVE-2019-9506: watchOS 5.3
vendor_apple·2019-07-22·CVSS 8.1
CVE-2019-9506 [HIGH] CVE-2019-9506: watchOS 5.3
Apple Security Update: About the security content of watchOS 5.3
Product: watchOS
Version: 5.3
CVE: CVE-2019-9506
Component: Bluetooth
Impact: An attacker in a privileged network position may be able to intercept Bluetooth traffic (Key Negotiation of Bluetooth - KNOB)
Description: An input validation issue existed in Bluetooth. This issue was addressed with improved input validation.
Debian
CVE-2019-9506: linux - The Bluetooth BR/EDR specification up to and including version 5.1 permits suffi...
vendor_debian·2019·CVSS 8.1
CVE-2019-9506 [HIGH] CVE-2019-9506: linux - The Bluetooth BR/EDR specification up to and including version 5.1 permits suffi...
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.
Scope: local
bookworm: resolved (fixed in 5.2.6-1)
bullseye: resolved (fixed in 5.2.6-1)
forky: resolved (fixed in 5.2.6-1)
sid: resolved (fixed in 5.2.6-1)
trixie: resolved (fixed in 5.2.6-1)
Cisco
Key Negotiation of Bluetooth Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-9506 Key Negotiation of Bluetooth Vulnerability
CVE-2019-9506: Key Negotiation of Bluetooth Vulnerability
A weakness in the Bluetooth Basic Rate/Enhanced Data Rate (BR/EDR) protocol core specification exposes a vulnerability that could allow for an unauthenticated, adjacent attacker to perform a man-in-the-middle attack on an encrypted Bluetooth connection. The attack must be performed during negotiation or renegotiation of a paired device connection; existing sessions cannot be attacked. The issue could allow the attacker to reduce the entropy of the negotiated session key that is used to secure a Bluetooth connection between a paired device and a host device. An attacker who can successfully inject a malicious message into a Bluetooth connection during session negotiation or renegotiation could cause the strength of the session key to
GHSA
GHSA-5xj4-2499-67mw: The Bluetooth BR/EDR specification up to and including version 5
ghsa_unreviewed·2022-05-24
CVE-2019-9506 [HIGH] CWE-327 GHSA-5xj4-2499-67mw: The Bluetooth BR/EDR specification up to and including version 5
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.
OSV
linux, linux-aws, linux-azure, linux-gcp, linux-gke-5.0, linux-hwe, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2019-10-04·CVSS 7.4
CVE-2019-0136 [HIGH] linux, linux-aws, linux-azure, linux-gcp, linux-gke-5.0, linux-hwe, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-azure, linux-gcp, linux-gke-5.0, linux-hwe, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that the Intel Wi-Fi device driver in the Linux kernel
did not properly validate certain Tunneled Direct Link Setup (TDLS). A
physically proximate attacker could use this to cause a denial of service
(Wi-Fi disconnect). (CVE-2019-0136)
It was discovered that the Bluetooth UART implementation in the Linux
kernel did not properly check for missing tty operations. A local attacker
could use this to cause a denial of service. (CVE-2019-10207)
It was discovered that the GTCO tablet input driver in the Linux kernel did
not properly bounds check the initial HID report sent by the device. A
physically proximate attacker could use this to cause a denial
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2 regression
osv·2019-09-11·CVSS 4.6
[MEDIUM] linux, linux-aws, linux-aws-hwe, linux-azure, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2 regression
linux, linux-aws, linux-aws-hwe, linux-azure, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2 regression
USN 4115-1 fixed vulnerabilities in the Linux 4.15 kernel for Ubuntu
18.04 LTS and Ubuntu 16.04 LTS. Unfortunately, as part of the update,
a regression was introduced that caused a kernel crash when handling
fragmented packets in some situations. This update addresses the issue.
We apologize for the inconvenience.
Original advisory details:
Hui Peng and Mathias Payer discovered that the Option USB High Speed driver
in the Linux kernel did not properly validate metadata received from the
device. A physically proximate attacker could use this to cause a denial of
service (system crash). (CVE-2018-19985)
Zhipeng Xie discovered that an infinite loop could tr
OSV
linux, linux-azure, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2 vulnerabilities
osv·2019-09-02·CVSS 4.6
CVE-2018-19985 [MEDIUM] linux, linux-azure, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2 vulnerabilities
linux, linux-azure, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2 vulnerabilities
Hui Peng and Mathias Payer discovered that the Option USB High Speed driver
in the Linux kernel did not properly validate metadata received from the
device. A physically proximate attacker could use this to cause a denial of
service (system crash). (CVE-2018-19985)
Zhipeng Xie discovered that an infinite loop could be triggered in the CFS
Linux kernel process scheduler. A local attacker could possibly use this to
cause a denial of service. (CVE-2018-20784)
It was discovered that the Intel Wi-Fi device driver in the Linux kernel did
not properly validate certain Tunneled Direct Link Setup (TDLS). A
physically proximate attacker could use this to cause a denial of service
(Wi-Fi
OSV
linux-aws vulnerabilities
osv·2019-09-02·CVSS 3.3
CVE-2018-13053 [LOW] linux-aws vulnerabilities
linux-aws vulnerabilities
It was discovered that the alarmtimer implementation in the Linux kernel
contained an integer overflow vulnerability. A local attacker could use
this to cause a denial of service. (CVE-2018-13053)
Wen Xu discovered that the XFS filesystem implementation in the Linux
kernel did not properly track inode validations. An attacker could use this
to construct a malicious XFS image that, when mounted, could cause a denial
of service (system crash). (CVE-2018-13093)
Wen Xu discovered that the f2fs file system implementation in the Linux
kernel did not properly validate metadata. An attacker could use this to
construct a malicious f2fs image that, when mounted, could cause a denial
of service (system crash). (CVE-2018-13096, CVE-2018-13097, CVE-2018-13098,
CVE-2018-1309
OSV
CVE-2019-9506: The Bluetooth BR/EDR specification up to and including version 5
osv·2019-08-14·CVSS 8.1
CVE-2019-9506 [HIGH] CVE-2019-9506: The Bluetooth BR/EDR specification up to and including version 5
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage
blogs_talos·2019-08-13·CVSS 9.1
[CRITICAL] Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage
Microsoft released its monthly security update today, disclosing a variety of vulnerabilities in several of its products. The latest Patch Tuesday covers 97 vulnerabilities, 31 of which are rated “critical," 65 that are considered "important" and one "moderate."
This month’s security update covers security issues in a variety of Microsoft services and software, including certain graphics components, Outlook and the Chakra Scripting Engine. For more on our coverage of these bugs, check out our Snort advisories here, covering all of the new rules we have for this release.
### Critical vulnerabilities Microsoft disclosed 31 critical vulnerabilities this month, three of which we will highlight below.
CVE-2019-1181 and CVE-2019-1182 are both remote code execution vulnerabilities in Remote De
Talos
Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage
blogs_talos·2019-08-13·CVSS 9.8
[CRITICAL] Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage
## Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage
Microsoft released its monthly security update today, disclosing a variety of vulnerabilities in several of its products. The latest Patch Tuesday covers 97 vulnerabilities, 31 of which are rated “critical," 65 that are considered "important" and one "moderate."
This month’s security update covers security issues in a variety of Microsoft services and software, including certain graphics components, Outlook and the Chakra Scripting Engine. For more on our coverage of these bugs, check out our Snort advisories here , covering all of the new rules we have for this release.
## Critical vulnerabilities Microsoft disclosed 31 critical vulnerabilities this month, three of which we will highlight below.
CVE-2
arXiv
On managing vulnerabilities in AI/ML systems
arxiv_fulltext·2021-01-22
On managing vulnerabilities in AI/ML systems
On managing vulnerabilities in AI/ML systems
Jonathan M. Spring
jspring AT sei dot cmu dot edu
0000-0001-9356-219X
CERT Coordination Center\ Engineering Institute\ Mellon University
Pittsburgh
PA
15213
April Galyardt
Software Engineering Institute\ Mellon University
Pittsburgh
PA
15213
Allen D. Householder
0000-0001-8970-4108
CERT Coordination Center\ Engineering Institute\ Mellon University
Pittsburgh
PA
15213
Nathan VanHoudnos
Software Engineering Institute\ Mellon University
Pittsburgh
PA
15213
Spring, Galyardt, Householder, and VanHoudnos
## Abstract
This paper explores how the current paradigm of vulnerability management might adapt to include machine learning systems through a
thought experiment: what if flaws in *ML were assigned *CVE-ID?
We consider both *ML algorithms a
Bugzilla
CVE-2020-10135 kernel: bluetooth: BR/EDR Bluetooth Impersonation Attacks (BIAS)
bugzilla·2020-05-06·CVSS 8.1
CVE-2020-10135 [HIGH] CVE-2020-10135 kernel: bluetooth: BR/EDR Bluetooth Impersonation Attacks (BIAS)
CVE-2020-10135 kernel: bluetooth: BR/EDR Bluetooth Impersonation Attacks (BIAS)
A vulnerability affecting Bluetooth BR/EDR pairing was found in the Bluetooth Core specification versions 1.0 through 5.2. The flaw could allow an attacking device to spoof the address of a previously paired remote device to successfully complete the authentication procedure with some paired/bonded devices while not possessing the link key. This can permit an attacker to initiate the Bluetooth Key Negotiation attack (KNOB) on encryption key strength without intervening in an ongoing pairing procedure through an injection attack.
Discussion:
Acknowledgments:
Name: CERT
---
As per the report, for this attack to be successful several conditions are to be met:
- the attacker needs to be within wireless range
Bugzilla
CVE-2019-9506 kernel: : hardware: bluetooth : BR/EDR encryption key negotiation attacks (KNOB) [fedora-all]
bugzilla·2019-08-19·CVSS 8.1
CVE-2019-9506 [HIGH] CVE-2019-9506 kernel: : hardware: bluetooth : BR/EDR encryption key negotiation attacks (KNOB) [fedora-all]
CVE-2019-9506 kernel: : hardware: bluetooth : BR/EDR encryption key negotiation attacks (KNOB) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affec
Bugzilla
CVE-2019-9506 hardware: bluetooth: BR/EDR encryption key negotiation attacks (KNOB)
bugzilla·2019-07-08·CVSS 8.1
CVE-2019-9506 [HIGH] CVE-2019-9506 hardware: bluetooth: BR/EDR encryption key negotiation attacks (KNOB)
CVE-2019-9506 hardware: bluetooth: BR/EDR encryption key negotiation attacks (KNOB)
The Bluetooth BR/EDR encryption key negotiation protocol is vulnerable to packet injection that could allow an unauthenticated user to decrease the size of the entropy of the encryption key, potentially causing information disclosure and/or escalation of privileges via adjacent access. There is not currently any knowledge of this being exploited.
Note:
Not all bluetooth devices are vulnerable to this flaw. Only devices that can connect to another using BR/EDR encryption negotiation protocol.
CERT notification:
https://kb.cert.org/vuls/id/918987/
Upstream patches:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=d5bb334a8e171b262e48f378bd2096c0ea458265
https://git.kernel.or
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00036.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00037.htmlhttp://seclists.org/fulldisclosure/2019/Aug/11http://seclists.org/fulldisclosure/2019/Aug/13http://seclists.org/fulldisclosure/2019/Aug/14http://seclists.org/fulldisclosure/2019/Aug/15http://www.cs.ox.ac.uk/publications/publication12404-abstract.htmlhttp://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190828-01-knob-enhttps://access.redhat.com/errata/RHSA-2019:2975https://access.redhat.com/errata/RHSA-2019:3055https://access.redhat.com/errata/RHSA-2019:3076https://access.redhat.com/errata/RHSA-2019:3089https://access.redhat.com/errata/RHSA-2019:3165https://access.redhat.com/errata/RHSA-2019:3187https://access.redhat.com/errata/RHSA-2019:3217https://access.redhat.com/errata/RHSA-2019:3218https://access.redhat.com/errata/RHSA-2019:3220https://access.redhat.com/errata/RHSA-2019:3231https://access.redhat.com/errata/RHSA-2019:3309https://access.redhat.com/errata/RHSA-2019:3517https://access.redhat.com/errata/RHSA-2020:0204https://lists.debian.org/debian-lts-announce/2019/09/msg00014.htmlhttps://lists.debian.org/debian-lts-announce/2019/09/msg00015.htmlhttps://lists.debian.org/debian-lts-announce/2019/09/msg00025.htmlhttps://usn.ubuntu.com/4115-1/https://usn.ubuntu.com/4118-1/https://usn.ubuntu.com/4147-1/https://www.bluetooth.com/security/statement-key-negotiation-of-bluetooth/https://www.kb.cert.org/vuls/id/918987/https://www.usenix.org/conference/usenixsecurity19/presentation/antoniolihttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00036.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00037.htmlhttp://seclists.org/fulldisclosure/2019/Aug/11http://seclists.org/fulldisclosure/2019/Aug/13http://seclists.org/fulldisclosure/2019/Aug/14http://seclists.org/fulldisclosure/2019/Aug/15http://www.cs.ox.ac.uk/publications/publication12404-abstract.htmlhttp://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190828-01-knob-enhttps://access.redhat.com/errata/RHSA-2019:2975https://access.redhat.com/errata/RHSA-2019:3055https://access.redhat.com/errata/RHSA-2019:3076https://access.redhat.com/errata/RHSA-2019:3089https://access.redhat.com/errata/RHSA-2019:3165https://access.redhat.com/errata/RHSA-2019:3187https://access.redhat.com/errata/RHSA-2019:3217https://access.redhat.com/errata/RHSA-2019:3218https://access.redhat.com/errata/RHSA-2019:3220https://access.redhat.com/errata/RHSA-2019:3231https://access.redhat.com/errata/RHSA-2019:3309https://access.redhat.com/errata/RHSA-2019:3517https://access.redhat.com/errata/RHSA-2020:0204https://lists.debian.org/debian-lts-announce/2019/09/msg00014.htmlhttps://lists.debian.org/debian-lts-announce/2019/09/msg00015.htmlhttps://lists.debian.org/debian-lts-announce/2019/09/msg00025.htmlhttps://usn.ubuntu.com/4115-1/https://usn.ubuntu.com/4118-1/https://usn.ubuntu.com/4147-1/https://www.bluetooth.com/security/statement-key-negotiation-of-bluetooth/https://www.kb.cert.org/vuls/id/918987/https://www.usenix.org/conference/usenixsecurity19/presentation/antonioli
2019-08-14
Published